Privacy Policy
Effective date: 1 June 2025 · Governed under the Digital Personal Data Protection Act, 2023 (DPDP Act)
This Privacy Policy describes how MAGADH IT AND CONSULTANCY SERVICES PRIVATE LIMITED ("we", "us", "our") collects, uses, stores, and protects your personal data when you use e-Court at https://e-court.mics.asia. By using the platform, you consent to this policy.
1. Information We Collect
A. Account & Identity Data
- Full name and email address when you register
- Phone number (if provided)
- Password — stored as an irreversible bcrypt hash; we never store plaintext passwords
- Profile photo URL (from OAuth providers or uploaded by you)
- Business / law firm details (if provided)
B. OAuth Sign-in Data (Google · Microsoft · Yahoo)
- OAuth provider user ID, display name, email address, and profile picture
- Access token and refresh token — stored securely to enable calendar sync features
- Token expiry time and granted OAuth scopes
- Google Calendar (calendar.events scope) — read/write access requested only to create, update, and delete hearing reminders you set inside e-Court; we do not read, store, or share any other calendar events
C. Device, Session & Usage Data
- IP address at registration and each login
- Approximate geolocation derived from IP (country, city, latitude/longitude) — never GPS or precise location
- Browser name and version, operating system, device type (mobile/tablet/desktop)
- User-agent string
- Pages visited, features used, and time spent (aggregated, not linked to identity for analytics)
- Session activity timestamps used for inactivity-based auto-logout
D. Legal & Case Data
- Case details, hearing dates, court orders, and notes you enter
- Client and contact information you add to the platform
- Documents and files you upload
- Tasks, calendar events, and reminders you create
- Messages exchanged within the platform
E. Payment Information
- Payment and billing details processed through our payment providers
- We do not store full card numbers — payments are handled by PCI-compliant providers
2. How We Use Your Information
We process your personal data for the following purposes:
- Authenticate you and maintain your session securely
- Create and manage your workspace, cases, hearings, tasks, and documents
- Sync hearing reminders to your connected Google or Microsoft calendar
- Send transactional emails: email verification, password reset, security alerts, and order confirmations
- Process payments and maintain billing records
- Detect and prevent unauthorized access by cross-checking session IP and device data
- Respond to support queries and grievances
- Improve platform stability and fix bugs using aggregated, anonymised usage signals
- Comply with Indian law, including the DPDP Act 2023, Information Technology Act 2000, and applicable rules
We do not sell, rent, or trade your personal data to third parties. We do not use your data for advertising or marketing to third parties.
3. Data Storage & Security
- All data is stored on servers located in India
- Data in transit is protected by TLS 1.2 / 1.3 (HTTPS) at all times
- Passwords are hashed with bcrypt — irreversible, never stored in plaintext
- OAuth tokens are stored encrypted at the database level
- Sessions are JWT-based; session records are stored in our database and can be remotely revoked by you at any time
- Session logs are automatically capped and purged to limit data retention
- We conduct regular security reviews and dependency audits
Despite these measures, no internet system is 100% secure. If you suspect unauthorised access to your account, please contact us immediately at admin@mics.asia.
4. Data Sharing & Third-Party Services
We share information only in these limited circumstances:
- Service providers for payments, KYC verification, and customer support — under strict data processing agreements
- Legal or regulatory authorities when required by law or to protect rights
- Third parties only with your explicit, informed consent
Third-party integrations:
Google (OAuth + Calendar API)
Sign-in and calendar event sync. Governed by Google's Privacy Policy & Terms of Service.
Microsoft Azure AD (OAuth + Outlook Calendar)
Sign-in and calendar event sync. Governed by Microsoft's Privacy Statement.
Yahoo (OAuth)
Sign-in only. Governed by Yahoo's Privacy Policy.
IP Geolocation Service
Converts your IP to approximate city/country for security logging. No other personal data is shared.
Payment Gateway
Processes billing transactions under PCI-DSS compliance. We do not store raw card data.
5. Cookies & Local Storage
- Authentication session cookies (HttpOnly, Secure flag) — required for login; cannot be disabled
- "ecourt_oauth_intent" cookie — tracks sign-in vs. account-linking intent during OAuth flow; deleted automatically after the flow completes
- Theme preference stored in localStorage (light / dark / system) — purely functional
- We do not use advertising cookies, third-party tracking pixels, or cross-site trackers
6. Your Rights under the DPDP Act 2023
As a data principal under the Digital Personal Data Protection Act, 2023, you have the right to:
Access
Obtain a summary of personal data we process about you and the purposes for processing
Correction & Erasure
Request correction of inaccurate or incomplete data, or deletion of data no longer necessary for the stated purpose
Grievance Redressal
File a complaint with our Grievance Officer (details below); unresolved complaints may be escalated to the Data Protection Board of India after 30 days
Nomination
Nominate another individual to exercise your data rights in case of death or incapacity
Withdraw Consent
Withdraw consent for data processing at any time; withdrawal does not affect lawfulness of prior processing
Revoke OAuth Access
Disconnect your Google / Microsoft account from Settings → Linked Accounts at any time
To exercise any right, email us at admin@mics.asia. We respond within 48 hours and resolve within 30 days.
7. Data Retention
- Active account data is retained while your account exists
- Session logs are capped at 100 entries per user; older entries are automatically purged
- When you delete your account, all personal data is permanently deleted within 30 days
- Payment records may be retained for 7 years as required by Indian tax and financial regulations
- Anonymised, aggregated analytics data may be retained indefinitely
8. Children's Privacy
e-Court is intended for legal professionals and adults (18+ years). We do not knowingly collect personal data from minors. If we become aware that a minor has provided personal data, we will delete it promptly. If you believe a minor has registered, please contact us at admin@mics.asia.
9. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will update the effective date at the top. For material changes, we will notify registered users via email at least 7 days before the change takes effect. Continued use after the effective date constitutes acceptance of the revised policy.
10. Grievance Officer & Contact
In accordance with the Digital Personal Data Protection Act, 2023, and the Information Technology Act, 2000, the contact details of the Grievance Officer are:
Shwetank Dhar
Grievance Officer
MAGADH IT AND CONSULTANCY SERVICES PRIVATE LIMITED
Badarpur, New Delhi & Varanasi, Uttar Pradesh, India
Response time: within 48 hours
Resolution time: within 30 days
Unresolved complaints may be escalated to the Data Protection Board of India